Data access abnormity identification method, electronic equipment and computer readable medium
By adding an abnormal access identification system between the data packet aggregator and the data acquisition system and updating statistical records to identify and locate data packet access anomalies, the problem of inaccurate fault location in the existing technology is solved, and the accuracy of data analysis and system performance are improved.
Patent Information
- Application Number
- CN202410381202.9
- Authority / Receiving Office
- CN · China
- Patent Type
- Applications(China)
- Current Assignee / Owner
- Filing Date
- 2024-03-28
- Publication Date
- 2025-09-30
AI Technical Summary
In the prior art, when an access anomaly occurs during the transmission of a data packet, it is difficult to accurately locate the source of the fault, resulting in inaccurate data analysis and increased network resource consumption.
By adding an abnormal access identification system between the data packet aggregator and the data acquisition system, the statistical information in the first statistical record is updated, the target statistical record is generated, the abnormalities in the data packet access process are identified, and the fault is quickly located by analyzing the abnormal type and source.
It achieves accurate identification of data packet access anomalies and rapid fault location, improving the accuracy of data analysis and system performance.
Smart Images

Figure CN120729699A_ABST
Abstract
Description
Technical Field
[0001] The present disclosure relates to the field of communication technology, and in particular to a method for identifying data access anomalies, an electronic device, and a computer-readable medium. Background Art
[0002] In the communications field, data collection and analysis of packets transmitted between network elements is used to identify user activity and network transmission quality, and has been widely used around the world. For example, data collection systems in the IP (Internet Protocol) communications field.
[0003] However, in actual applications, data packet transmission failures often occur due to incorrect network layout or configuration of data acquisition equipment. In order to analyze the cause of the failure, how to accurately locate the data access anomaly of the network element device that transmits the data packet is an urgent problem that needs to be solved. Summary of the Invention
[0004] In response to the above-mentioned deficiencies in the prior art, the present disclosure provides a method for identifying data access anomalies, an electronic device, and a computer-readable medium.
[0005] In a first aspect, an embodiment of the present disclosure provides a method for identifying data access anomalies, the method comprising:
[0006] updating statistical information in the first statistical record according to a first address pair corresponding to the received data packet to obtain a target statistical record; the first address pair is information capable of identifying a source network element and a destination network element of the data packet;
[0007] Identify whether there is any anomaly in the statistical information of the target statistical record.
[0008] In a second aspect, an embodiment of the present disclosure provides an electronic device, including:
[0009] one or more processors;
[0010] A memory having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method for identifying data access anomalies described in the first aspect.
[0011] In a third aspect, an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon, which, when executed by a processor, implements the method for identifying data access anomalies described in the first aspect.
[0012] In a fourth aspect, an embodiment of the present disclosure provides a computer program product, comprising a computer program or computer instructions, wherein the computer program or the computer instructions are stored in a computer-readable storage medium, a processor of a computer device reads the computer program or the computer instructions from the computer-readable storage medium, and the processor executes the computer program or the computer instructions, so that the computer device executes: the method for identifying data access anomalies as described in the first aspect.
[0013] The disclosed embodiments provide a method for identifying data access anomalies, an electronic device, a computer-readable medium, and a computer program product. In the disclosed embodiments, by updating the statistical information of a first address pair in a first statistical record to obtain a target statistical record, it is possible to accurately identify, based on the statistical information in the target statistical record, whether an anomaly occurs during the access of a data packet between a mobile communication network to a data acquisition device. In the event of an anomaly, the anomaly type can be accurately determined by analyzing the statistical information of the anomaly. The network element device corresponding to the address pair where the anomaly occurs can also be determined based on the anomaly type, thereby ensuring the timely discovery of the source of the fault. BRIEF DESCRIPTION OF THE DRAWINGS
[0014] Figure 1 A schematic diagram of an application scenario of a method for identifying abnormal data access provided by an embodiment of the present disclosure;
[0015] Figure 2 A flowchart of a method for identifying data access anomalies provided by an embodiment of the present disclosure;
[0016] Figure 3 This is a flowchart of a specific implementation method of step S1 in the embodiment of the present disclosure;
[0017] Figure 4 This is a flowchart of a specific implementation method of step S4 in the embodiment of the present disclosure;
[0018] Figure 5 A schematic structural diagram of an electronic device provided in an embodiment of the present disclosure;
[0019] Figure 6 A schematic diagram of the structure of a computer-readable medium provided in an embodiment of the present disclosure;
[0020] Figure 7 A schematic diagram of the structure of an exemplary abnormal access identification system provided by an embodiment of the present disclosure;
[0021] Figure 8 A schematic diagram of a processing flow of a data packet parser in an exemplary abnormal access identification system provided by an embodiment of the present disclosure;
[0022] Figure 9A schematic diagram of the processing flow of a data packet counter in an exemplary abnormal access identification system provided by an embodiment of the present disclosure. DETAILED DESCRIPTION
[0023] To enable those skilled in the art to better understand the technical solution of the present disclosure, the data access anomaly identification method, electronic device, and computer-readable medium provided by the present disclosure are described in detail below with reference to the accompanying drawings.
[0024] Example embodiments will be described more fully hereinafter with reference to the accompanying drawings, but the example embodiments may be embodied in different forms and should not be construed as limited to the embodiments set forth herein. Rather, these embodiments are provided so that this disclosure will be thorough and complete and will fully convey the scope of this disclosure to those skilled in the art.
[0025] In the absence of conflict, the various embodiments of the present disclosure and the various features therein may be combined with each other.
[0026] As used herein, the term "and / or" includes any and all combinations of one or more of the associated listed items.
[0027] The terms used herein are used only to describe specific embodiments and are not intended to limit the present disclosure. As used herein, the singular forms "a," "an," and "the" are also intended to include the plural forms, unless the context clearly indicates otherwise. It will also be understood that when the terms "comprising" and / or "made of" are used in this specification, the presence of the features, wholes, steps, operations, elements, and / or components is specified, but the presence or addition of one or more other features, wholes, steps, operations, elements, components, and / or groups thereof is not excluded.
[0028] Unless otherwise defined, all terms (including technical and scientific terms) used herein have the same meaning as commonly understood by one of ordinary skill in the art. It will also be understood that terms such as those defined in commonly used dictionaries should be interpreted as having a meaning consistent with their meaning in the context of the relevant art and the present disclosure, and will not be interpreted as having an idealized or overly formal meaning unless expressly defined as such herein.
[0029] Figure 1 This is a schematic diagram of an application scenario of a method for identifying abnormal data access provided by an embodiment of the present disclosure. Figure 1In an IP communication system, a routing device interacts with multiple communication clients (e.g., a first communication client, a second communication client) and multiple communication servers (e.g., a first communication server, a second communication server), and a data packet aggregator aggregates data packets from multiple sources (i.e., communication clients and communication servers) in the IP communication system through an optical splitter of the communication client and an optical splitter of the communication server. In some related technologies, all data packets aggregated by the data packet aggregator are input into a data acquisition system to realize IP packet data acquisition. However, there often occur abnormal states such as no access to communication data packets between some IP address pairs, only unilateral data access to communication data packets, or illegal access to communication data packets. The causes of these abnormal states are often complex and difficult to locate. For example, abnormal states may occur due to changes in the network structure of the IP communication system, upgrades, changes, or abnormalities in the data packet aggregator, abnormalities in the communication client or communication server, upgrades, changes, or abnormalities in the data acquisition system, etc. Furthermore, these abnormal conditions can directly or indirectly lead to other problems. For example, if data packets from an IP address pair are missing or only accessed, the data analysis system will obtain inaccurate results. If data packets from an illegal IP address pair are accessed, the data collection system will be overloaded, thus affecting its collection performance. Therefore, a solution is urgently needed to accurately locate data access anomalies in network element devices that transmit data packets.
[0030] In a related technology, if the data acquisition and analysis systems detect an anomaly in data packet transmission, they use a reverse engineering approach to check each front-end device (i.e., the communication client and communication server) for anomalies. If an anomaly is found, the access policy is readjusted to ensure accurate data access. However, this method of troubleshooting and preventing abnormal access is relatively passive, inefficient, and lacks intelligence. In practical applications, it can negatively impact product quality and user experience.
[0031] In another related technology, a data collection system filters illegally accessed data packets based on IP addresses, allowing legitimate IP addresses to access corresponding data packets while prohibiting illegitimate IP addresses from accessing corresponding data packets. However, since it is impossible to accurately locate and resolve the source of the problem of illegally accessed data packets, even if the illegally accessed data packets are filtered, the problem of illegally accessed data packets and network resource consumption still persists.
[0032] The embodiment of the present disclosure is to add an abnormal access identification system between the data packet aggregator and the data acquisition system. The abnormal access identification system can execute a method for identifying data access anomalies, so as to accurately identify whether an abnormality occurs in the process of data packets between mobile communication networks accessing the data acquisition device based on the statistical information in the target statistical record. In the event of an abnormality, the type and source of the abnormality can be accurately determined through further analysis of the abnormal statistical information, thereby ensuring the timeliness of discovering the source of the fault, thereby helping to quickly repair access fault problems that occur in the IP communication system and its data acquisition system. In some embodiments, the process of data packets between mobile communication networks accessing the data acquisition device is through methods such as optical splitting and copying, and the present disclosure is not limited to this.
[0033] Figure 2 A flowchart of a method for identifying abnormal data access provided by an embodiment of the present disclosure. Figure 2 The present disclosure provides a method for identifying abnormal data access, the method comprising:
[0034] S1. Update statistical information in a first statistical record according to a first address pair corresponding to a received data packet to obtain a target statistical record; the first address pair is information that can identify a source network element and a destination network element of the data packet;
[0035] S2. Identify whether there is any abnormality in the statistical information in the target statistical record.
[0036] The embodiment of the present disclosure obtains a target statistical record by updating the statistical information in the first statistical record, thereby accurately identifying whether an abnormality occurs in the process of data packets between mobile communication networks being accessed by the data acquisition device based on the statistical information in the target statistical record. In the event that an abnormality occurs in the statistical information in the target statistical record, the abnormal statistical information can be further analyzed to accurately determine the type of abnormality and the network element device that caused the abnormality (i.e., the source of the abnormality). At the same time, since the statistical information records the transmission of data packets by the first address within a cumulative range, the identification of abnormalities in the statistical information in the target statistical record can also effectively ensure the timeliness of discovering the source of the fault.
[0037] The first statistical record is the most recently updated statistical record. It is updated sequentially based on the most recent statistical record (i.e., the first statistical record) according to the first address pair corresponding to the received data packet, thereby ensuring real-time identification of data access anomalies. The embodiments of the present disclosure do not specifically limit the format of the statistical record; it can be a table, a database storing statistical information, or other storage format that can effectively store statistical information.
[0038] In some embodiments, before S1, the method further includes:
[0039] The first statistical record is created according to the target address pair in the preset working parameter table.
[0040] The target address pair in the pre-set working parameter table can also be referred to as working parameter information in the working parameter table. The first statistical record created before being updated is the initial statistical record. The fields of the first statistical record, the target statistical record, and the initial statistical record are all the same. That is, the first statistical record can be updated based on the initial statistical record, and the target statistical record is a statistical record obtained by updating the first statistical record. The fields of the statistical record include at least the first address pair, so that when updating the first statistical record, the record item to be updated can be determined based on the first address pair.
[0041] Abnormal statistical information refers to one or more record items in the identified target statistical record that are in an abnormal state. Each record item in an abnormal state corresponds to a first address pair. By analyzing the abnormal statistical information and its corresponding first address pair, the source and type of the abnormality can be determined. The "source" of the abnormality refers to the network element that caused the abnormal state. Specifically, it can be the source network element corresponding to the first address pair, the destination network element, or both the source network element and the destination network element. The abnormality type refers to the classification of the abnormal state. By determining the source and type of the abnormality, the source of the fault can be quickly discovered, helping to quickly repair access faults.
[0042] In some embodiments, the first address pair includes a source Internet Protocol IP address corresponding to a source network element and a destination IP address corresponding to a destination network element;
[0043] Alternatively, the first address pair includes a source signaling point address number corresponding to a source network element and a destination signaling point address number corresponding to a destination network element.
[0044] In this embodiment, the first address pair is information that can identify the source network element and destination network element of a data packet. The source network element of a data packet refers to the message sender of the data packet, and the destination network element of a data packet refers to the message receiver of the data packet. In different network architectures, the information used to identify the source network element and the destination network element may be the same or different. In a network architecture based on the Internet Protocol (IP), an IP address uniquely identifies a network element device. Specifically, the source IP address uniquely identifies the source network element, and the destination IP address uniquely identifies the destination network element. In a network architecture based on protocols related to signaling control, a signaling point code (SPC) is an address number set to identify each signaling point (including signaling transfer points) in a signaling network. Each signaling point has a unique address number used for routing signaling messages within the signaling network. Signaling point codes are independent, so a network element device can be uniquely identified by its signaling point address number. Specifically, the source signaling point address number uniquely identifies the source network element, and the destination signaling point address number uniquely identifies the destination network element.
[0045] The embodiments of the present disclosure do not impose special restrictions on the network architecture. For network architectures corresponding to protocols other than Internet Protocol (IP) and non-signaling control-related protocols, the information that can uniquely identify the source network element and the destination network element can also be used as an address pair.
[0046] In some embodiments, the statistical information includes at least one of the following:
[0047] A valid flag, used to identify the legitimacy of transmitting a data packet through the first address pair;
[0048] The number of data packets is used to identify the total number of data packets transmitted by the first address pair in the corresponding transmission direction;
[0049] Latest time, used to identify the time point when the first address pair last transmitted a data packet;
[0050] The initial time is used to identify the time point when the first address pair transmits a data packet for the first time.
[0051] In this embodiment, the fields of a statistical record include at least one address pair and its statistical information. The address pair is a required field in the statistical record, and the statistical information records the statistics of data packets transmitted through the address pair. That is, each address pair in the fields of the statistical record is fixed. In some embodiments, address pairs can be added, deleted, or modified, but their changes do not change with the statistical status of the data packets. However, the statistics corresponding to the address pairs do change with the statistical status of the data packets. For example, the number of data packets corresponding to the address pair "10.0.1.1" and "10.0.1.2" will increase by 1 upon receiving a data packet corresponding to the address pair. It is worth noting that the required fields in the statistical record may also include the transmission direction corresponding to the address pair, the interface name corresponding to the address pair, etc., but this disclosure is not limited to these fields. An address pair includes information about at least two addresses corresponding to the source network element and the destination network element; the transmission direction corresponding to the address pair refers to the path or direction of the data packet transmitted within the address pair.
[0052] The valid mark in the statistical information is used to identify the legality of the data packet transmitted through the address pair, so that it can be determined whether the data packet corresponding to the first address pair is an illegally accessed data packet based on the validity or invalidity of the valid mark. The number of data packets is used to identify the total number of data packets transmitted by the first address pair in the corresponding transmission direction, so that it can be determined whether there is data access for the address pair in the corresponding transmission direction based on the number of data packets. It can also be determined whether there are abnormal conditions such as unilateral non-access anomalies, bilateral non-access anomalies, or message disproportion based on the number of data packets for the same first address pair in different transmission directions. The transmission time includes the latest time and the initial time, wherein the latest time and the initial time are used to identify the time points of the first address pair's most recent and first data packet transmissions, respectively. The latest time and the initial time can be used to assist in determining whether there are abnormal conditions such as unilateral non-access anomalies, bilateral non-access anomalies, or message disproportion.
[0053] In some embodiments, before S1, the method further includes:
[0054] The data packet is subjected to protocol layer parsing processing to obtain a first address pair corresponding to the data packet.
[0055] In embodiments of the present disclosure, data packets are typically encapsulated and transmitted across multiple protocol layers. Protocol layer parsing of a data packet refers to parsing the data packet layer by layer, extracting information from each protocol layer as needed, and thereby obtaining a first address pair. In some embodiments, protocol layer parsing may include decapsulation, field parsing, and protocol header parsing of the data packet, but the present disclosure is not limited thereto.
[0056] As an example, the first data packet obtained by aggregation is subjected to protocol layer parsing. The protocol corresponding to the protocol layer of the first data packet is the Internet Protocol IP. Therefore, the first data packet is subjected to protocol layer parsing. The Source Address field corresponding to the IP protocol layer of the first data packet is used as the source IP. The source IP can identify the source network element of the first data packet. The Destination Address field corresponding to the IP protocol layer of the first data packet is used as the destination IP. The destination IP can identify the destination network element of the first data packet, thereby determining that the first address pair corresponding to the first data packet is the source IP and the destination IP.
[0057] In some embodiments, after performing protocol layer parsing on the data packet to obtain the first address pair corresponding to the data packet, the method further includes:
[0058] Searching for target working parameter information of the first address pair corresponding to the data packet in a preset working parameter table;
[0059] When the target work parameter information is found, the data packet is forwarded to the data acquisition system, and / or the valid mark of the target statistical information of the first address pair corresponding to the data packet is recorded as valid, or,
[0060] In the case that the target work parameter information is not found, the validity mark of the target statistical information of the first address pair corresponding to the data packet is recorded as invalid.
[0061] In an embodiment of the present disclosure, a pre-set working parameter table is generated based on working parameter information (i.e., target address pairs). The working parameter information is the equipment layout information of a real communication network, which is deterministic and unique, and is conducive to ensuring the accuracy of illegal access judgment. The embodiment of the present disclosure does not impose any special restrictions on the method of obtaining working parameter information. It can be directly obtained and imported from the operating manufacturer, or it can be obtained by configuration. The necessary information items in the working parameter information are at least one target address pair, and the target address pairs are all legal address pairs. In some embodiments, the working parameter information may also include the name of the source network element corresponding to the target address pair, the name of the destination network element, and the interface name, etc. The present disclosure is not limited to this, wherein the name of the source network element corresponding to the target address pair, the name of the destination network element corresponding to the target address pair, and the interface name, etc. are all optional information items in the working parameter information.
[0062] The pre-set working parameter table records the target address pairs corresponding to legally accessed data packets. Since the working parameter table is generated based on working parameter information, and the required information item in the working parameter information is at least one target address pair, in some embodiments, the target address pairs in the working parameter information can be used as legally accessed address pairs to generate the working parameter table. Each address pair in the working parameter table corresponds one-to-one to a target address pair in the working parameter information.
[0063] Since the pre-set industrial parameter table records the information of the target address pair corresponding to the legally accessed data packet, after parsing and obtaining the first address pair of the data packet, the industrial parameter table is searched for target industrial parameter information consistent with the first address pair (i.e., the address pair corresponding to the legally accessed data packet), thereby determining whether the data packet corresponding to the first address pair is legally accessed. In the case that the target industrial parameter information consistent with the first address pair (i.e., the target address pair) can be found, the data packet is determined to be a legally accessed data packet, the data packet corresponding to the first address pair can be collected, and the data packet is forwarded to the data acquisition system. In some embodiments, in the case that the target industrial parameter information is not found, the data packet corresponding to the first address pair is discarded, and the valid mark of the target statistical information of the first address pair corresponding to the data packet is recorded as invalid. That is, in the case that the target industrial parameter information is not found, the data packet is determined to be an illegally accessed data packet, and the data packet corresponding to the first address pair is discarded, thereby filtering the illegally accessed data packet, avoiding the continued collection and analysis of the illegally accessed data packet, and improving the system performance and the accuracy of data analysis.
[0064] It is worth noting that the initial statistical record is also created based on the engineering parameter information of the target address pair. The fields in the initial statistical record include the fields in the engineering parameter information. For example, if the fields in the engineering parameter information include the target address pair (source IP address and destination IP address), transmission direction, and interface name, then the fields in the initial statistical record also include the target address pair (source IP address and destination IP address), transmission direction, and interface name. Since the necessary information item in the engineering parameter information is at least one target address pair, the address pair is also a necessary information item in the fields of the initial statistical record. In addition, the fields in the initial statistical record also include statistical information corresponding to the address pair, such as the above-mentioned valid mark, number of data packets, latest time, initial time, etc.
[0065] The following describes the initial creation rules for creating an initial statistical record (i.e., a first statistical record that has not been updated) based on the work parameter information including at least one target address pair:
[0066] The fields in the initial statistical record include the target address pair. If the engineering parameter information also includes optional information items (such as the name of the source network element corresponding to the target address pair, the name of the destination network element corresponding to the target address pair, and the interface name), corresponding fields can also be generated based on these optional information items. The fields related to statistical information in the initial statistical record can be set according to actual needs.
[0067] Import the target address pair in the work parameter information as the address pair in the initial statistical record to obtain the target address pair and its corresponding transmission direction of the initial statistical record;
[0068] Import the optional information items in the work parameter information as the optional information items in the initial statistical record;
[0069] Set the valid information in the statistical information corresponding to the imported address pairs to valid (e.g., set to TRUE), set the number of data packets in the statistical information corresponding to the imported address pairs to the initial value (e.g., set the initial value to 0), set the latest time in the statistical information corresponding to the imported address pairs to an invalid value (e.g., set the initial value to 0), and set the initial time in the statistical information corresponding to the imported address pairs to an invalid value (e.g., set the initial value to 0).
[0070] It is worth noting that the address pairs in the initial statistical record correspond one-to-one to the target address pairs in the work parameter information, but after the initial statistical record is updated, the statistical record may also include the address pairs and statistical information corresponding to the illegally accessed data packets.
[0071] As an example, the process of determining the transmission direction corresponding to the address pair of the initial statistical record based on the target address pair in the imported working parameter information is as follows: the data packet transmitted from the user side to the network side is regarded as having an upstream transmission direction (i.e., the source IP address is the IP address of the user side, and the destination IP address is the IP address of the network side), and the data packet transmitted from the network side to the user side is regarded as having a downstream transmission direction (i.e., the source IP address is the IP address of the network side, and the destination IP address is the IP address of the user side).
[0072] As another example, the working parameter information obtained by directly obtaining and importing from the operating manufacturer is shown in Table 1:
[0073] Table 1
[0074] User-side IP address Network-side IP address User-side NE name Network side NE name Interface Name 10.0.1.1 10.0.1.2 Network element 1 Network element 2 Interface 1 10.0.2.1 10.0.2.2 Network Element 3 Network Element 4 Interface 2 ...... ...... ...... ...... ......
[0075] Among them, the user-side IP address and the network-side IP address are necessary information items in the engineering parameter information, while the user-side network element name, the network-side network element name and the interface name are optional information items in the engineering parameter information.
[0076] According to the working parameter information in Table 1, a pre-set working parameter table is generated, as shown in Table 2:
[0077] Table 2
[0078] User-side IP address Network-side IP address 10.0.1.1 10.0.1.2 10.0.2.2 10.0.2.1 ...... ......
[0079] The first pair of addresses in the industrial parameter table is: the user side IP address is 10.0.1.1, and the network side IP address is 10.0.1.2. The second pair of addresses is: the user side IP address is 10.0.2.2, and the network side IP address is 10.0.2.1. There is a one-to-one correspondence between the address pairs in the industrial parameter table and the target address pairs in the industrial parameter information in Table 1.
[0080] Based on the work parameter information in Table 1, the initial statistical information is created, as shown in Table 3:
[0081] Table 3
[0082]
[0083] The source IP address is the address information of the source network element, and the destination IP address is the address information of the destination network element. The source IP address and destination IP address form an address pair, and each address pair corresponds to one piece of statistical information. Data packets transmitted from the user side to the network side are considered to be transmitted in the uplink direction, while data packets transmitted from the network side to the user side are considered to be transmitted in the downlink direction. The interface name corresponding to the target address pair in the initial statistical information is consistent with the interface name in the engineering parameter information. The valid information corresponding to the target address pair in the initial statistical information is uniformly set to the initial value "valid". Data packets transmitted by these address pairs with valid information are all legally accessed data packets. The number of packets corresponding to the target address pair in the initial statistical information indicates the total number of data packets received by this target address pair in this transmission direction. Since data packet aggregation has not yet been performed when the initial statistical information is created, the number of packets is set to the initial value of 0. The initial time corresponding to the target address pair in the initial statistical information indicates the time when the first data packet was received by this target address pair in this transmission direction. Since data packet aggregation has not yet been performed when the initial statistical information is created, the initial time is set to the initial value of 0. The latest time corresponding to the destination address pair in the initial statistical information is used to identify the time point of the last data packet received by the destination address pair and the transmission direction. Since data packet aggregation has not been performed when the initial statistical information is created, the latest time is set to the initial value 0.
[0084] When the second data packet is converged, the protocol layer parsing is performed on the second data packet, and the first address pair corresponding to the second data packet is obtained as the source IP address 10.0.2.2 and the destination IP address 10.0.2.1. By searching the first address pair corresponding to the second data packet in Table 2 (i.e., the work parameter table), the target address pair corresponding to the second data packet can be found. Therefore, the second data packet is a legally accessed data packet, and the second data packet can be collected.
[0085] When the third data packet is converged, the protocol layer parsing is performed on the third data packet, and the first address pair corresponding to the third data packet is obtained as the source IP address 10.0.2.5 and the destination IP address 10.0.2.6. By searching the first address pair corresponding to the third data packet in Table 2 (i.e., the working parameter table), the target address pair corresponding to the third data packet is not found, so the third data packet is an illegally accessed data packet, and the third data packet is discarded to avoid the illegally accessed third data packet from continuing to be collected and analyzed.
[0086] Figure 3 This is a flow chart of a specific implementation method of step S1 in the embodiment of the present disclosure. Figure 3 In some embodiments, S1 includes:
[0087] S11. Searching for a target address pair in the first statistical record; the target address pair is consistent with the first address pair corresponding to the data packet;
[0088] S121. When the target address pair is found, update the statistical information corresponding to the target address pair in the first statistical record according to the first address pair to obtain a target statistical record, or
[0089] S122: If the target address pair is not found, add the first address pair to the first statistical record and configure statistical information of the first address pair according to the first address pair to obtain a target statistical record.
[0090] In an embodiment of the present disclosure, statistics are collected for all the data packets that are aggregated. That is, regardless of whether the corresponding target working parameter information of the data packet can be found in the working parameter table, the data packet needs to be updated in the first statistical record. A target address pair that is consistent with the first address pair is searched in the first statistical record. If the target address pair is found, it is determined that the first address pair has been counted before. Then, the updated target statistical record can be obtained by directly updating the statistical information based on the found target address pair. If the target address pair is not found, it means that the first address pair has not been counted before. Then, a new record item needs to be created for the first address pair in the first statistical record, that is, the first address pair is added and the statistical information of the first address pair is configured to obtain the target statistical record.
[0091] It is worth noting that in some embodiments, since the address pairs corresponding to legal access in the statistical information are imported through the work parameter information when the initial statistical information is created, if the target address pair is not found from the first statistical record, it can be determined that the first address pair is illegal, that is, the data packet corresponding to the first address pair is illegally accessed.
[0092] In some embodiments, updating statistical information corresponding to the target address pair in the first statistical record includes:
[0093] The number of data packets or transmission time corresponding to the target address pair in the first statistical record is updated.
[0094] In this embodiment, the transmission time includes the initial time of the first transmission of the data packet corresponding to the target address pair and the latest time of the most recent transmission of the data packet.
[0095] As an example, updating statistical information corresponding to the target address pair in the first statistical record includes at least one of the following:
[0096] Add 1 to the number of data packets corresponding to the target address pair in the first statistical record;
[0097] Updating the latest time corresponding to the target address pair in the first statistical record to the current time point;
[0098] The initial time and the latest time corresponding to the target address pair in the first statistical record are updated to the current time point.
[0099] In this embodiment, a target address pair that is consistent with the first address pair is found, and it is determined that the corresponding statistical information existed before for the first address pair. In the case where the statistical information includes the number of data packets, it is necessary to add 1 to the number of data packets in the statistical information to indicate that the total number of times the address pair corresponding to the statistical information transmits data packets in the corresponding transmission direction is added by 1. In the case where the statistical information includes the latest time, the latest time is updated to the current time point to indicate that the current time point is the moment when the address pair most recently transmitted a data packet in the corresponding transmission direction. In the case where the statistical information includes the initial time, and the data packet transmitted this time is the first time that the target address pair transmits a data packet, both the initial time and the latest time are updated to the current time point to indicate that the current time point is the moment when the address pair first and most recently transmitted a data packet in the corresponding transmission direction.
[0100] In some embodiments, adding the first address pair to the first statistical record and configuring statistical information of the first address pair includes:
[0101] At least one of the number of data packets, the valid flag, and the transmission time corresponding to the first address pair is added to the first statistical record; the added valid flag indicates that the first address pair is illegal.
[0102] In this embodiment, if the target address pair is not found, it means that the first address pair is an illegal address pair, and the data packet transmitted through the illegal first address pair is invalid. Therefore, when configuring the statistical information of the first address pair, the valid mark of the first address pair is determined to be invalid.
[0103] As an example, the configuring of the statistical information of the first address pair includes at least one of the following:
[0104] Setting the number of data packets corresponding to the first address pair to 1;
[0105] Setting the valid flag corresponding to the first address pair to invalid;
[0106] Setting the initial time corresponding to the first address pair to the current time point;
[0107] The latest time corresponding to the first address pair is set as the current time point.
[0108] In this embodiment, if the target address pair consistent with the first address pair is not found, it is determined that the first address pair does not have corresponding statistical information before, that is, it has not been recorded by the first statistical record. In the case where the statistical information includes the number of data packets, the number of data packets in the statistical information needs to be set to 1 to indicate that the total number of times the first address pair corresponding to the statistical information transmits data packets in the corresponding transmission direction is 1. In the case where the statistical information includes a valid mark, the valid mark is set to invalid to indicate that the transmission of data packets by the first address pair in the corresponding transmission direction is an illegal access. In the case where the statistical information includes an initial time, the initial time is set to the current time point to indicate that the current time point is the moment when the first address pair first transmits a data packet in the corresponding transmission direction. In the case where the statistical information includes the latest time, the latest time is set to the current time point to indicate that the current time point is the moment when the first address pair last transmitted a data packet in the corresponding transmission direction.
[0109] In some embodiments, S2 includes:
[0110] If the first address pair of the statistical information is illegal, determining that an abnormality exists in the statistical information;
[0111] In the case where the number of data packets in the statistical information is abnormal, determining that the statistical information is abnormal;
[0112] When the transmission time of the statistical information is abnormal, it is determined that the statistical information is abnormal.
[0113] As an example, when the first address pair of the statistical information is illegal, determining that the statistical information is abnormal includes: when the valid mark of the statistical information is invalid, determining that the statistical information is abnormal.
[0114] As another example, when the number of data packets in the statistical information is abnormal, determining that the statistical information is abnormal includes:
[0115] When the number of data packets corresponding to the first transmission direction of the statistical information is less than a first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to a second preset number, determining that the statistical information is abnormal;
[0116] When the number of data packets corresponding to the first transmission direction of the statistical information is less than a third preset number and the number of data packets corresponding to the second transmission direction is less than a fourth preset number, determining that the statistical information is abnormal;
[0117] When the difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction in the statistical information is greater than or equal to a fifth preset number, it is determined that there is an abnormality in the statistical information.
[0118] As another example, when the transmission time of the statistical information is abnormal, determining that the statistical information is abnormal includes:
[0119] When the number of data packets in the statistical information changes and the latest time does not change, it is determined that an abnormality exists in the statistical information.
[0120] In some embodiments, when there is an anomaly in the statistical information in the target statistical record, the method further includes:
[0121] S3. Determine the abnormality type corresponding to the abnormal statistical information; the abnormality type includes at least one of illegal access, unilateral non-access abnormality, bilateral non-access abnormality, message disproportion, and midway non-access abnormality.
[0122] In the embodiment of the present disclosure, since the valid information is used to identify the legitimacy of transmitting a data packet through an address pair, when the valid mark of the abnormal statistical information is invalid, the abnormal type corresponding to the abnormal statistical information is illegal access.
[0123] Since the number of packets is used to identify the total number of packets transmitted for an address pair in the corresponding transmission direction, at least three types of exceptions may occur: unilateral non-access exception, bilateral non-access exception, or message disproportion.
[0124] Among them, a unilateral non-access exception refers to a situation where the number of data packets corresponding to the first transmission direction of the abnormal statistical information is less than the first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to the second preset number. The data packet has a non-access exception in the first transmission direction corresponding to the address pair, but the data packet can be accessed normally in the second transmission direction corresponding to the address pair, which is equivalent to a non-access exception in one of the two different transmission directions of the same address pair (i.e., the first transmission direction).
[0125] A bilateral non-access anomaly occurs when the number of packets corresponding to the first transmission direction in the anomaly statistics information is less than a third preset number and the number of packets corresponding to the second transmission direction is less than a fourth preset number. A non-access anomaly occurs in both the first and second transmission directions corresponding to the address pair, and the source of the anomaly is the network element identified by the address pair corresponding to the first and second transmission directions. In some embodiments, the third and fourth preset numbers are set to 0.
[0126] Message disproportionality means that, when the difference between the number of packets corresponding to the first transmission direction and the number of packets corresponding to the second transmission direction in the abnormal statistical information is greater than or equal to a fifth preset number, the number of packets transmitted in the first transmission direction is disproportionate to the number of packets transmitted in the second transmission direction. It is worth noting that message disproportionality can indicate either an abnormal state or a normal state of the network element, depending on the specific service.
[0127] The latest time identifies the time when the address pair last transmitted a data packet. Therefore, if the number of packets in the abnormal statistics changes within a cumulative time range but the latest time remains unchanged, it means that the address pair has not transmitted any data packets since the latest time. In other words, the abnormality type corresponding to the abnormal statistics is a missed connection abnormality.
[0128] It is worth noting that the first preset number, the second preset number, the third preset number, the fourth preset number and the fifth preset number may be the same number or different numbers, and the present disclosure is not limited thereto.
[0129] In some embodiments, the target statistical records are displayed in the form of a visual interface so that users can intuitively understand the address pairs where abnormal conditions occur and their statistical information, so that they can accurately locate the network element devices (source network elements and / or destination network elements) that cause the abnormal conditions, the type of abnormality, the time when the abnormality occurs, the time when the abnormality is eliminated, etc., to provide guidance for troubleshooting and provide a visual basis for tracking the progress of troubleshooting.
[0130] In some embodiments, when there is an anomaly in the statistical information in the target statistical record, the method further includes at least one of the following:
[0131] In a case where the first address pair of the statistical information is illegal, determining the source network element identified by the first address pair as the abnormal source of the statistical information;
[0132] When the number of data packets corresponding to the first transmission direction of the statistical information is less than a first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to a second preset number, determining the source network element identified by the first address pair as the abnormal source of the statistical information;
[0133] When the number of data packets corresponding to the first transmission direction of the statistical information is less than a third preset number and the number of data packets corresponding to the second transmission direction is less than a fourth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal source of the statistical information;
[0134] If a difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to a fifth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal source of the statistical information;
[0135] In a case where the number of data packets in the statistical information changes and the latest time does not change, the destination network element identified by the first address pair is determined as the abnormal source of the statistical information.
[0136] In the embodiment of the present disclosure, the abnormal source refers to the network device that causes the statistical information of the abnormal type to appear.
[0137] The illegality of the first address pair in the statistical information specifically means that the first address pair is inconsistent with the address pair specified in the work parameter information. Therefore, the source of the abnormality is the source network element identified in the address pair. That is to say, the source network element generates an illegally accessed data packet, resulting in an illegal access problem when the data packet is transmitted through the address pair.
[0138] In the case of a unilateral non-access exception, that is, the number of data packets corresponding to the first transmission direction of the statistical information is less than the first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to the second preset number, the data packets have a non-access exception in the first transmission direction corresponding to the first address pair, and can be accessed normally in the second transmission direction corresponding to the first address pair, which is equivalent to a non-access exception in one of the two different transmission directions of the same address pair (that is, the first transmission direction). Therefore, the source of the exception is the source network element identified by the address pair corresponding to the first transmission direction.
[0139] In the case of bilateral non-access anomaly, that is, the number of data packets corresponding to the first transmission direction of the statistical information is less than the third preset number and the number of data packets corresponding to the second transmission direction is less than the fourth preset number, the data packets have non-access anomalies in both the first transmission direction and the second transmission direction corresponding to the address pair. Therefore, the source of the anomaly is the network element identified by the address pair corresponding to the first transmission direction and the second transmission direction, that is, anomalies have occurred in both the source network element and the destination network element.
[0140] In the case of disproportionate messages, that is, when the difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to the fifth preset number, the number of data packets transmitted in the first transmission direction is disproportionate to the number of data packets transmitted in the second transmission direction. Therefore, the source of the abnormality is the source network element and the destination network element identified by the address pair.
[0141] In the case of no access exception in the middle, that is, when the number of data packets in the abnormal statistical information changes within a cumulative time range and the latest time does not change, it means that the address pair has not transmitted any data packets after the latest time, so the source of the exception is the destination network element identified by the address pair corresponding to the abnormal statistical information.
[0142] The present disclosure does not specifically limit the analysis process of the target statistical records. In some embodiments, abnormal statistical information and its corresponding abnormal source and / or abnormal type can also be identified from the target statistical records through manual analysis.
[0143] As an example, data packet access starts at 00:00 on January 1, 2024. Table 4 below shows the second statistical information corresponding to 06:00 on January 1, 2024:
[0144] Table 4
[0145]
[0146] As shown in Table 4, the source IP address 10.0.1.1 and the destination IP address 10.0.1.2 are an address pair with an upstream transmission direction, while the source IP address 10.0.1.2 and the destination IP address 10.0.1.1 are an address pair with a downstream transmission direction. From 00:00 on January 1, 2024, to 06:00 on January 1, 2024, the validity flag is valid, indicating that the data packets corresponding to this address pair have legal access. The number of data packets transmitted in the upstream direction for this address pair is 6,000,000, while the number of data packets transmitted in the downstream direction for this address pair is 0. The first preset number and the second preset number are both 0. Therefore, abnormal statistical information has occurred in the downstream transmission direction. The abnormality type is a unilateral non-access abnormality. The source of the abnormality is the network element with the source IP address 10.0.1.2 in the downstream transmission direction. Access in the upstream transmission direction is normal.
[0147] The source IP address 10.0.2.1 and the destination IP address 10.0.2.2 are an address pair with an upstream transmission direction. The source IP address 10.0.2.2 and the destination IP address 10.0.2.1 are an address pair with a downstream transmission direction. From 00:00 on January 1, 2024, to 06:00 on January 1, 2024, the validity flag is valid, indicating that the data packets corresponding to this address pair are legally accessed. The number of data packets transmitted in both the upstream and downstream directions for this address pair is 0, and the fourth preset number is 0. Therefore, abnormal statistical information has occurred in both the upstream and downstream transmission directions. The abnormality type is a bilateral non-access abnormality, and the sources of the abnormality are the network element with the address 10.0.2.1 and the network element with the address 10.0.2.2.
[0148] The source IP address 10.0.3.1 and the destination IP address 10.0.3.2 are an address pair with an upstream transmission direction. The source IP address 10.0.3.2 and the destination IP address 10.0.3.1 are an address pair with a downstream transmission direction. From 00:00 on January 1, 2024 to 06:00 on January 1, 2024, the valid mark is valid, indicating that the data packets corresponding to this address pair are legally accessed. The number of data packets transmitted in both the upstream and downstream directions for this address pair is 1,000,000. Combined with the latest time, it can be seen that the address pair last transmitted a data packet in both the upstream and downstream directions at 01:00 on 2024-01-01. Analysis shows that this address pair has experienced an anomaly type of mid-way bilateral access failure since 01:00 on 2024-01-01. The anomaly sources are the network elements with addresses 10.0.3.1 and 10.0.3.2.
[0149] The address pair with source IP address 20.0.0.1 and destination IP address 20.0.0.2 had the first access time at 00:00 on 2024-01-01 and the most recent access time at 06:00 on 2024-01-01 between 00:00 and 06:00 on 2024-01-01. The number of packets was 6,000,000 and the valid flag was invalid, indicating that the packets corresponding to this address pair were illegally accessed.
[0150] The address pair with source IP address 20.0.0.2 and destination IP address 20.0.0.1 had the first access time at 00:00 on 2024-01-01 and the most recent access time at 06:00 on 2024-01-01 between 00:00 and 06:00 on 2024-01-01. The number of packets was 6,000,000 and the valid flag was invalid, indicating that the packets corresponding to this address pair were illegally accessed.
[0151] Figure 4 This is a flow chart of a specific implementation method of step S4 in the embodiment of the present disclosure. Figure 4 In some embodiments, after S3, the method further includes:
[0152] S4. When there is an abnormality in the statistical information in the target statistical record, determine the abnormality elimination situation corresponding to the abnormal statistical information.
[0153] In the embodiments of the present disclosure, based on the analysis of the target statistical record, it is possible to quickly locate whether an abnormality occurs in the network element corresponding to the address pair corresponding to the statistical information, and at the same time, the abnormality type and / or the source of the abnormality can be quickly and accurately located. Analyzing the abnormality type and the source of the abnormality can guide rapid and thorough troubleshooting. By analyzing the changes in the target statistical record of the statistical information with abnormalities, it is possible to effectively determine the abnormality elimination situation corresponding to the abnormal statistical information, that is, to determine whether the abnormal source of the abnormal statistical information has been processed, so that data packets can be transmitted normally through the address pair, and continuous tracking of data packets corresponding to the address pair of the abnormal statistical information is achieved, thereby deriving the progress of troubleshooting. The present disclosure does not make special restrictions on the abnormality elimination situation, and may include the abnormality resolution situation (such as whether the abnormality is partially resolved or completely resolved), the abnormality resolution time, etc.
[0154] It is worth noting that the timing of the occurrence of the abnormal statistical information can be further determined based on the abnormal statistical information and its dynamic changes. The timing of the occurrence of the abnormal statistical information here can be an access exception when the program is started, or an access exception during the program operation. The present disclosure is not limited to this.
[0155] In some embodiments, when the abnormality type of the statistical information is a unilateral non-access abnormality, a bilateral non-access abnormality, or an intermediate non-access abnormality in the first transmission direction, determining the abnormality elimination situation corresponding to the abnormal statistical information includes:
[0156] When the change corresponding to the statistical information is that the number of data packets corresponding to the first transmission direction and the second transmission direction is greater than or equal to the sixth preset number, and the latest time changes synchronously with the number of data packets, it is determined that the abnormality exclusion situation corresponding to the abnormal statistical information is that the abnormality has been repaired.
[0157] In this embodiment, if the abnormality type of the abnormal statistical information in the target statistical record is a unilateral non-access abnormality in the first transmission direction, a bilateral non-access abnormality in the first transmission direction and the second transmission direction, or a midway non-access abnormality, but after analyzing the changes in the abnormal statistical information, it is determined that the number of data packets in the abnormal statistical information has returned to normal counting, and the latest time is synchronized with the change in the number of data packets, then it means that the address pair has restored access to data packets, and therefore the abnormal exclusion situation corresponding to the abnormal statistical information is that the abnormality has been repaired.
[0158] In some embodiments, when the abnormal type of the statistical information is illegal access, determining the abnormality elimination situation corresponding to the abnormal statistical information includes:
[0159] When the valid mark corresponding to the abnormal statistical information is invalid within the preset time period and the number of data packets and the latest time are unchanged, it is determined that the abnormality elimination situation corresponding to the statistical information is that the abnormality has been repaired.
[0160] In this embodiment, if the abnormality type of the statistical information in the target statistical record is illegal access, but after analyzing the changes in the statistical information, it is determined that the number of data packets and the latest time of the statistical information no longer change, then it means that no new illegal access data packets are generated, indicating that the access failure caused by the illegal access address has been eliminated, and the time of eliminating the failure is the time point corresponding to the latest time field, so the abnormality elimination situation corresponding to the statistical information is that the abnormality has been repaired.
[0161] As another example, data packets are accessed starting at 00:00 on January 1, 2024. After identifying the statistical information in Table 4 at 06:00 on January 1, 2024, the following abnormal statistical information is determined:
[0162] 1) The source IP address is 10.0.1.2, and the destination IP address is 10.0.1.1. The corresponding statistical information for the address pair with the transmission direction being downlink is the statistical information of unilateral non-access exception.
[0163] 2) The statistical information corresponding to the address pair with the source IP address 10.0.2.1 and the destination IP address 10.0.2.2 (transmission direction is upstream) and the address pair with the source IP address 10.0.2.2 and the destination IP address 10.0.2.1 (transmission direction is downstream) is the statistical information of bilateral non-access anomalies;
[0164] 3) The source IP address 10.0.3.1 and the destination IP address 10.0.3.2 are the address pairs with the transmission direction being upstream. The source IP address 10.0.3.2 and the destination IP address 10.0.3.1 are the address pairs with the transmission direction being downstream. The corresponding statistical information is the statistical information of the mid-way bilateral non-access anomaly.
[0165] 4) The statistical information corresponding to the address pair with the source IP address 20.0.0.1 and the destination IP address 20.0.0.2 is the statistical information of illegal access;
[0166] 5) The statistical information corresponding to the address pair with the source IP address of 20.0.0.2 and the destination IP address of 20.0.0.1 is the statistical information of illegal access.
[0167] The fault was corrected between 06:00 AM on January 1, 2024, and 08:00 AM on January 1, 2024. Based on Table 4, data aggregation statistics were continued. Table 5 shows the third statistical information corresponding to 08:00 AM on January 1, 2024:
[0168] Table 5
[0169]
[0170]
[0171] By analyzing the statistical information of the anomalies (1) to (5) and their changes in Tables 4 and 5, it can be seen that during the period from 06:00 on 2024-01-01 to 08:00 on 2024-01-01:
[0172] 1) The source IP address is 10.0.1.2, and the destination IP address is 10.0.1.1. The transmission direction is downlink. The corresponding exception type is unilateral access failure. The anomaly troubleshooting status is that the anomaly has been fixed. Referring to the initial time, it can be seen that the fault was fixed at 07:00 on 2024-01-01.
[0173] 2) For the address pairs with source IP address 10.0.2.1 and destination IP address 10.0.2.2 (transmission direction is uplink), and for the address pairs with source IP address 10.0.2.2 and destination IP address 10.0.2.1 (transmission direction is downlink), the exception type corresponding to the bilateral access failure statistics is resolved. The initial time indicates that the fault was resolved at 07:00 on January 1, 2024.
[0174] 3) The source IP address 10.0.3.1 and the destination IP address 10.0.3.2 are address pairs with an upstream transmission direction. The source IP address 10.0.3.2 and the destination IP address 10.0.3.1 are address pairs with a downstream transmission direction. The corresponding exception type is a bilateral non-access exception in the middle of the transmission. The exception exclusion situation of the statistical information is that the exception of the upstream address pair has been repaired, while the abnormal state of the downstream address pair is already in an abnormal state. Therefore, the exception type of the downstream address pair is changed to a unilateral non-access exception.
[0175] 4) The abnormality elimination status of the statistical information corresponding to the abnormality type of illegal access for the address pair with the source IP address of 20.0.0.1 and the destination IP address of 20.0.0.2 is that the abnormality has been fixed. According to the latest time, the fault was eliminated at 06:00 on 2024-01-01;
[0176] 5) The abnormality elimination status of the statistical information of the illegal access corresponding to the address pair with the source IP address of 20.0.0.2 and the destination IP address of 20.0.0.1 is that the abnormality has been fixed. Referring to the latest time, it can be seen that the fault was eliminated at 06:00 on 2024-01-01.
[0177] The above-mentioned embodiment of the present disclosure obtains the target statistical record by updating the statistical information of the address pair in the first statistical record, so that it can accurately identify whether there is an abnormality in the process of data packets between mobile communication networks accessing the data acquisition device based on the statistical information in the target statistical record. In the event of an abnormality, the network element device corresponding to the address pair with the abnormality can be accurately determined by analyzing the statistical information, while ensuring the timeliness of discovering the source of the fault.
[0178] Furthermore, on the basis of quickly locating the type and source of anomalies, it is also possible to track the results of fault repairs through continuous tracking of statistical information to completely eliminate abnormal access problems, reduce the workload of the data collection process, improve system performance, and enhance the network quality of data packet analysis and the accuracy of user behavior.
[0179] Secondly, refer to Figure 5 , an embodiment of the present disclosure provides an electronic device, comprising:
[0180] One or more processors 501;
[0181] A memory 502 storing one or more programs, which, when executed by one or more processors, enable the one or more processors to implement any of the aforementioned methods for identifying abnormal data access;
[0182] One or more I / O interfaces 503 are connected between the processor and the memory and are configured to implement information exchange between the processor and the memory.
[0183] Among them, the processor 501 is a device with data processing capabilities, including but not limited to a central processing unit (CPU); the memory 502 is a device with data storage capabilities, including but not limited to random access memory (RAM, more specifically SDRAM, DDR, etc.), read-only memory (ROM), electrically erasable programmable read-only memory (EEPROM), and flash memory (FLASH); the I / O interface (read-write interface) 503 is connected between the processor 501 and the memory 502, and can realize information interaction between the processor 501 and the memory 502, including but not limited to a data bus (Bus), etc.
[0184] Thirdly, refer to Figure 6 , an embodiment of the present disclosure provides a computer-readable medium having a computer program stored thereon, which implements any of the above-mentioned methods for identifying data access anomalies when the program is executed by a processor.
[0185] In a fourth aspect, an embodiment of the present disclosure provides a computer program product, which stores program instructions. When the program instructions are executed on a computer, the computer implements the method for identifying data access anomalies as described in any of the above embodiments.
[0186] In a specific embodiment, the above-mentioned computer program product can be used to implement each step of the method for identifying data access anomalies described in the first aspect.
[0187] In order to enable those skilled in the art to more clearly understand the technical solutions provided by the embodiments of the present disclosure, the technical solutions provided by the embodiments of the present disclosure are described in detail below through specific examples:
[0188] Example 1: Figure 7 This is a schematic diagram of the structure of an exemplary abnormal access identification system provided by an embodiment of the present disclosure. Figure 1 and Figure 7In an embodiment of the present disclosure, an abnormal access identification system is added between a data packet aggregator and a data acquisition system. This abnormal access identification system is used to implement the method for identifying abnormal data access described in the first aspect. The statistical record format in this embodiment is a table. The abnormal access identification system includes a configurator, a data packet receiver, a data packet transmitter, a data packet parser, a data packet counter, and a data packet access display. The functions of each module in the abnormal access identification system are described below:
[0189] The configurator is used to configure the abnormal access identification system. For example, the configurator controls whether the abnormal access identification system, located between the data packet aggregator and the data acquisition system, enables the data access anomaly identification function. Another example is the configurator importing industrial parameter information to generate an industrial parameter table and create an initial statistical table (i.e., an unupdated first statistical table).
[0190] The data packet receiver is used to establish and maintain a communication link between the abnormal access identification system and the data packet aggregator, and is also used to forward all data packets received by the data packet aggregator to the data packet parser.
[0191] The packet parser is used to perform protocol layer parsing on all packets forwarded by the packet receiver, obtain key information (i.e., the first address pair), construct a statistics request message based on the key information, and send the statistics request message to the packet counter. At the same time, the packet parser is also used to filter all packets forwarded by the packet receiver, that is, to compare the key information of the packet (i.e., the first address pair) with the address pairs in the working parameter table pre-set by the configurator. If an address pair that matches the key information can be found in the working parameter table, it indicates that the packet has been legally accessed and the packet is sent to the packet transmitter. Otherwise, it is an illegal access and is discarded.
[0192] The data packet transmitter is used to establish and maintain a communication link between the abnormal access identification system and the data acquisition system. At the same time, it is also used to forward the data packets transmitted after filtering by the data packet parser to the data acquisition system.
[0193] The data packet counter is used to receive the statistical request message sent by the data packet parser and update the statistical table according to the statistical request message. The statistical table is used to store the statistical information of the address pairs corresponding to all data packets so as to provide it to the data packet access display for visual display.
[0194] The data packet access displayer is used to display the statistical table maintained by the data packet counter in the form of a visual interface, so that users can intuitively understand the address pairs of abnormal access data packets and their statistical information, and can accurately locate the abnormal source (network element device), abnormal type, abnormal occurrence time, and abnormal elimination time of the data packet that caused the abnormal access, provide guidance for troubleshooting, and provide a visual basis for tracking the progress of troubleshooting.
[0195] The following describes the process of implementing data access anomaly identification methods in each module of the abnormal access identification system:
[0196] In step 701, the configurator imports the engineering parameter information into the abnormal access identification system to generate an engineering parameter table and create an initial statistical table. The engineering parameter information includes: address pairs (a set of user-side IP addresses and network-side IP addresses), user-side network element names, network-side network element names, and interface names. The statistical table fields include: address pairs (a set of source IP addresses and destination IP addresses), valid flag, number of packets, and transmission time (initial time and latest time).
[0197] In step 702, the packet parser performs protocol layer parsing on all packets received by the packet receiver from the packet aggregator to obtain the first address pair (i.e., key information) corresponding to each packet. Based on the parsed first address pair, the parsed packet parser constructs a statistics request message and sends the statistics request message to the packet counter for access packet statistics. The first address pair includes a source IP address and a destination IP address.
[0198] In step 703, the data packet parser searches the industrial parameter table based on the parsed first address pair. If an address pair consistent with the first address pair is successfully found in the industrial parameter table, the data packet is forwarded to the data packet transmitter so that the data packet transmitter sends the data packet to the data acquisition system. Otherwise, the data packet is discarded.
[0199] Step 704: The data packet counter updates the statistical table according to the first address in the received statistical request message, and sends the statistical information in the updated statistical table to the data packet access display for visual interface display.
[0200] In the first embodiment of the present disclosure, by analyzing the updated statistical table, the statistical information corresponding to various types of abnormalities (unilateral non-access abnormalities, bilateral non-access abnormalities, midway non-access abnormalities, illegal access, etc. in the first transmission direction) can be quickly and accurately located, and a visual interface display is performed through a data packet access display, allowing users to more intuitively understand the cause of the abnormal state (the source of the abnormality), and at the same time, quickly and accurately troubleshoot the problem.
[0201] Example 2: Figure 8This is a schematic diagram of the processing flow of a data packet parser in an exemplary abnormal access identification system provided by an embodiment of the present disclosure. Figure 1 、 7 8. The following describes the processing of the data packet parser:
[0202] Step 801: A data packet parser receives a data packet from a data packet transmitter, wherein the data packet transmitter forwards all data packets received by a data packet aggregator to the data packet parser.
[0203] In step 802 , the data packet analyzer determines whether the abnormal access automatic identification function of the abnormal access identification system is enabled. If enabled, step 803 is executed; otherwise, step 808 is executed.
[0204] Step 803: The data packet analyzer performs protocol layer analysis on the data packet to obtain key information of the data packet (ie, the first address pair), wherein the key information includes the source IP address and the destination IP address.
[0205] Step 804: The data packet parser constructs a statistics request message according to the key information of the data packet, and sends the statistics request message to the data packet counter.
[0206] In step 805, the data packet analyzer searches the preset working parameter table based on the key information (source IP address and destination IP address).
[0207] In step 806, the data packet analyzer determines whether an address pair that matches the key information can be found in the pre-set work parameter table. If so, step 808 is executed; otherwise, step 807 is executed.
[0208] Step 807: If no address pair consistent with the key information can be found in the work parameter table, it indicates that the data packet is an illegally accessed data packet (ie, the key information corresponding to the data packet is invalid), and the data packet parser discards it.
[0209] In step 808, if an address pair that matches the key information is found in the work parameter table, the packet is considered a legitimate access packet (i.e., the key information corresponding to the packet is valid), and the packet parser forwards it to the packet transmitter. Alternatively, if the abnormal access automatic identification function of the abnormal access identification system is not enabled, it is impossible to determine whether the packet is legitimate, and the packet parser forwards it to the packet transmitter.
[0210] In the second embodiment of the present disclosure, a data packet parser is used to parse the received data packet to obtain key information of the source network element and the destination network element of the data packet. The key information can be used to determine whether the data packet is legally accessed. The key information can uniquely determine the source network element and the destination network element, which is conducive to accurately judging the data packet of illegal access.
[0211] Example 3: Figure 9 This is a schematic diagram of the processing flow of a data packet counter in an exemplary abnormal access identification system provided by an embodiment of the present disclosure. Figure 1 、 7 9. The following describes the processing of the packet counter:
[0212] Step 901: The data packet counter receives a statistics request message sent by the data packet analyzer, wherein the statistics request message carries key information of the data packet, including the source IP address and the destination IP address.
[0213] In step 902, the data packet counter performs a query in the first statistics table using the source IP address and the destination IP address.
[0214] Step 903 , determining whether an address pair consistent with the source IP address and the destination IP address can be found in the first statistical table. If so, executing step 904 ; if not, executing step 905 .
[0215] In step 904, if the packet counter finds a matching source IP address and destination IP address in the first statistical table, this indicates that the source IP address and destination IP address have been previously counted by the first statistical table. The statistical information in the first statistical table is then updated. More specifically, the packet number field is incremented by 1, and the latest time field is updated to the current time point.
[0216] In step 905, if the packet counter fails to find an address pair that matches the source IP address and the destination IP address in the first statistical table, it means that the source IP address and the destination IP address have never been counted by the first statistical table before. Therefore, a new statistical record entry needs to be created in the first statistical table for the address pair of the source IP address and the destination IP address, i.e., the first address pair is added and the statistical information of the first address pair is configured. More specifically, the source IP address is set to the source IP address carried in the statistics request message, the destination IP address is set to the destination IP address carried in the statistics request message, the valid flag field is set to invalid, the packet number field is set to 1, the latest time field is set to the current time point, and the initial time field is set to the current time point.
[0217] In the third embodiment of the present disclosure, data packets are counted through a data packet counter, and the number of data packets (i.e., the number of data packets) and the access time of the data packets (such as the initial time and the latest time) are counted, thereby presenting statistical information about the address pair, so as to facilitate more clear presentation of statistical information when there are abnormalities in the statistical information (such as: abnormal access IP address pairs, abnormality types, abnormality occurrence time, abnormality sources, etc.).
[0218] It will be appreciated by those skilled in the art that all or some of the steps, systems, and functional modules / units in the methods disclosed above may be implemented as software, firmware, hardware, and appropriate combinations thereof. In hardware implementations, the division between the functional modules / units mentioned in the above description does not necessarily correspond to the division of physical components; for example, a physical component may have multiple functions, or a function or step may be performed by several physical components in cooperation. Some or all physical components may be implemented as software executed by a processor, such as a central processing unit, a digital signal processor, or a microprocessor, or implemented as hardware, or implemented as an integrated circuit, such as an application-specific integrated circuit. Such software may be distributed on a computer-readable medium, which may include a computer storage medium (or non-transitory medium) and a communication medium (or temporary medium). As is well known to those skilled in the art, the term computer storage medium includes volatile and non-volatile, removable, and non-removable media implemented in any method or technology for storing information (such as computer-readable instructions, data structures, program modules, or other data). Computer storage media includes, but is not limited to, RAM, ROM, EEPROM, flash memory or other memory technology, CD-ROM, digital versatile disks (DVD) or other optical disk storage, magnetic cassettes, magnetic tape, magnetic disk storage or other magnetic storage devices, or any other medium that can be used to store the desired information and can be accessed by a computer. In addition, it is well known to those skilled in the art that communication media typically embodies computer-readable instructions, data structures, program modules, or other data in a modulated data signal such as a carrier wave or other transport mechanism, and may include any information delivery media.
[0219] Example embodiments have been disclosed herein, and although specific terms are employed, they are used and should be interpreted only in a general illustrative sense and not for purposes of limitation. In some instances, it will be apparent to those skilled in the art that, unless otherwise expressly indicated, features, characteristics, and / or elements described in conjunction with a particular embodiment may be used alone or in combination with features, characteristics, and / or elements described in conjunction with other embodiments. Therefore, it will be understood by those skilled in the art that various changes in form and detail may be made without departing from the scope of the present disclosure as set forth in the appended claims.
Claims
1. A method for identifying data access anomalies, the method comprising: updating the statistical information in the first statistical record according to the first address pair corresponding to the received data packet to obtain a target statistical record; The first address pair is information capable of identifying a source network element and a destination network element of the data packet; Identify whether there is any anomaly in the statistical information of the target statistical record.
2. The method for identifying data access anomalies according to claim 1, wherein: The first address pair includes a source Internet Protocol IP address corresponding to a source network element and a destination IP address corresponding to a destination network element; Alternatively, the first address pair includes a source signaling point address number corresponding to a source network element and a destination signaling point address number corresponding to a destination network element.
3. The method for identifying data access anomalies according to claim 1, wherein: The updating of the statistical information in the first statistical record according to the first address pair corresponding to the received data packet to obtain the target statistical record includes: Searching for a target address pair in the first statistical record; the target address pair is consistent with the first address pair corresponding to the data packet; When the target address pair is found, the statistical information corresponding to the target address pair in the first statistical record is updated according to the first address pair to obtain a target statistical record, or In the case that the target address pair is not found, the first address pair is added to the first statistical record and statistical information of the first address pair is configured according to the first address pair to obtain a target statistical record.
4. The method for identifying data access anomalies according to claim 3, wherein: Updating statistical information corresponding to the target address pair in the first statistical record includes: The number of data packets or transmission time corresponding to the target address pair in the first statistical record is updated.
5. The method for identifying data access anomalies according to claim 3, wherein: The adding the first address pair to the first statistical record and configuring statistical information of the first address pair includes: At least one of the number of data packets, the valid flag, and the transmission time corresponding to the first address pair is added to the first statistical record; the added valid flag indicates that the first address pair is illegal.
6. The method for identifying data access anomalies according to claim 1, wherein: The statistical information includes at least one of the following: A valid flag, used to identify the legitimacy of transmitting a data packet through the first address pair; The number of data packets is used to identify the total number of data packets transmitted by the first address pair in the corresponding transmission direction; Latest time, used to identify the time point when the first address pair last transmitted a data packet; The initial time is used to identify the time point when the first address pair transmits a data packet for the first time.
7. The method for identifying data access anomalies according to claim 6, wherein: The identifying whether the statistical information in the target statistical record is abnormal includes at least one of the following: If the first address pair of the statistical information is illegal, determining that an abnormality exists in the statistical information; In the case where the number of data packets in the statistical information is abnormal, determining that the statistical information is abnormal; When the transmission time of the statistical information is abnormal, it is determined that the statistical information is abnormal.
8. The method for identifying data access anomalies according to claim 1, wherein: When there is an anomaly in the statistical information in the target statistical record, the method further includes: Determine the abnormality type corresponding to the abnormal statistical information; the abnormality type includes at least one of illegal access, unilateral non-access abnormality, bilateral non-access abnormality, message disproportion, and midway non-access abnormality.
9. The method for identifying data access anomalies according to claim 1, wherein: When the statistical information in the target statistical record is abnormal, the method further includes at least one of the following: In a case where the first address pair of the statistical information is illegal, determining the source network element identified by the first address pair as the abnormal source of the statistical information; When the number of data packets corresponding to the first transmission direction of the statistical information is less than a first preset number and the number of data packets corresponding to the second transmission direction is greater than or equal to a second preset number, determining the source network element identified by the first address pair as the abnormal source of the statistical information; When the number of data packets corresponding to the first transmission direction of the statistical information is less than a third preset number and the number of data packets corresponding to the second transmission direction is less than a fourth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal source of the statistical information; If a difference between the number of data packets corresponding to the first transmission direction and the number of data packets corresponding to the second transmission direction of the statistical information is greater than or equal to a fifth preset number, determining the source network element and the destination network element identified by the first address pair as the abnormal source of the statistical information; In a case where the number of data packets in the statistical information changes and the latest time does not change, the destination network element identified by the first address pair is determined as the abnormal source of the statistical information.
10. The method for identifying data access anomalies according to any one of claims 1 to 9, wherein: Before updating the statistical information in the first statistical record according to the first address pair corresponding to the received data packet to obtain the target statistical record, the method further includes: The first statistical record is created according to the target address pair in the preset working parameter table.
11. The method for identifying data access anomalies according to any one of claims 1 to 9, wherein: The method further comprises: Searching for target working parameter information of the first address pair corresponding to the data packet in a preset working parameter table; When the target work parameter information is found, the data packet is forwarded to the data acquisition system, and / or the valid mark of the target statistical information of the first address pair corresponding to the data packet is recorded as valid, or, In the case that the target work parameter information is not found, the validity mark of the target statistical information of the first address pair corresponding to the data packet is recorded as invalid.
12. An electronic device comprising: one or more processors; A memory having one or more programs stored thereon, wherein when the one or more programs are executed by the one or more processors, the one or more processors implement the method for identifying data access anomalies according to any one of claims 1 to 11.
13. A computer-readable medium having a computer program stored thereon, wherein when the program is executed by a processor, the method for identifying data access anomalies according to any one of claims 1 to 11 is implemented.
14. A computer program product, comprising a computer program or computer instructions, wherein the computer program or the computer instructions are stored in a computer-readable storage medium, a processor of a computer device reads the computer program or the computer instructions from the computer-readable storage medium, and the processor executes the computer program or the computer instructions, so that the computer device executes: the method for identifying data access anomalies as described in any one of claims 1 to 11.